CVE-2025-21418Active Exploitation(microsoft / windows_10_1607)

MEDIUMCVSS 7.8 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for microsoft windows_10_1607 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability

4.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-03-04. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-122

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-13); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2008windows_server_2012windows_server_2016

2 versions affected across 14 products

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-13: 1Mentions · 2026-08-15: 1Active Exploitation · 2026-08-13: 108-1308-15
Signal classification2 categories
Active Exploitation
150.0%
General
150.0%
Classification over time
DateTotalLabels
2026-08-131
Active Exploitation1
2026-08-151
General1
Full discourse2 posts
  • Human Firewall@HumanFirewallHQ
    Active Exploitation

    This is not afd.sys's first time. It's the FOURTH exploited zero-day in that same driver since 2022: CVE-2024-38193 (also Lazarus) CVE-2025-21418 CVE-2025-32709 CVE-2026-68820 (Lazarus, FudModule) One component, nation-state favorite.

    Post summary

    The tweet indicates that the afd.sys driver has been the target of four zero-day exploits across multiple CVEs, suggesting ongoing active exploitation in the wild.

    1000072
    2 followersView on X
  • Joshua Frank@PointFrankRange
    General

    Now pull up: CVE-2025-32709, CVE-2025-21418, CVE-2024-38193. Same driver. Lazarus was on that last one too. That’s four years of a nation-state mining one Windows component.

    Post summary

    The user simply lists three CVE identifiers and notes historical nation‑state interest in the same driver, but provides no technical, exploit, patch, or usage details.

    0000034
    44 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more